IBM i messages that will be written to Splunk are written to a log file in this directory:
Windows: \Program Files\EView Technology\EView400i\log
Linux: /var/opt/OV/log/vp400
The log’s filename will include the name of the IBM i LPAR that is being monitored. Each line of the log file is one message from the IBM i sent as JSON formatted field and value pairs.